I thought I had this fixed, but had my "exclude_files" line commented out. I moved the input up to the top and it still does not work. I am getting data from the other two inputs so I am thinking it has to do with this configuration setting. Any ideas would be appreciated!
I didn't change anything, but now I am seeing the postfix logs in ELK. This is just a small lab so its not heavily used so there shouldn't be any delay.
My custom filter/pattern is not working and I am getting a _grokparesfailure tag in Kibana. I am seeing this error in the logs? Can someone help me interpret the meaning?
That sounds more like a Logstash problem. One issue could be the following message: pattern %{OSTNAME:hostname} not defined" This should probably be HOSTNAME.
OK, I am VERY frustrated because its now working. The only thing I've done is reboot the server. Until then I was just restarting logstash & elasticsearch from the command line. Logstash sure is black magic at times.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.